
vlan配置
: | z0 Z9 {. |( H9 x1 e7 d3 m9 W4 F8 ]* T. S) a
interface Vlan110& k% |( z$ k3 v6 P; d* s
ip address 192.168.110.1 255.255.255.0; ?# E+ g3 B: q* t' b6 a7 h& S
ip access-group caiwuAllow in
. i7 F3 ?: x3 }; o ip helper-address 192.168.0.3. n6 k2 o# I+ G$ S' Q+ E' D& m
!/ O$ {' _/ k4 |$ Y' g J" R S3 b& g6 k
interface Vlan120
7 @3 Y/ ?1 W1 Q( P& e, w* Z; a6 T ip address 192.168.120.1 255.255.255.0
/ q: S/ b. z& {* [7 d ip access-group caiwuDeny in
@0 D. g3 M, Y& A/ R, O ip helper-address 192.168.0.3
# p+ [% O3 ~6 s6 ]) c# ?! e. R6 d" w9 E3 j1 N
interface Vlan130" ?( {& k3 ~ W1 z% u
ip address 192.168.130.1 255.255.255.0
" k. }6 N; d$ j" |# d ip access-group caiwuDeny in4 u* d4 [8 L9 |7 E: @) R
ip helper-address 192.168.0.3
6 g/ z0 ]+ p$ p7 {0 \ f!
" }; U U$ b# g" Hip access-list extended caiwuAllow
# W2 R, c$ R2 _( x; z permit ip 192.168.110.0 0.0.0.255 192.168.0.0 0.0.0.255 log reflect vlan110 timeout 30
, G1 ?* Y+ k0 C. Q' ~3 e2 ]+ v permit ip 192.168.110.0 0.0.0.255 192.168.120.0 0.0.0.255 log reflect vlan110 timeout 30- G# s4 `& q! `( u: r/ [2 ~
permit ip 192.168.110.0 0.0.0.255 192.168.130.0 0.0.0.255 log reflect vlan110 timeout 30' W8 [2 B& k% O
permit ip any any
* Q/ J- @. w! A8 z' Oip access-list extended caiwuDeny
' l% {' Z6 R/ }, A evaluate vlan110
) O! X; _* b5 F8 X) r9 ^& e) M deny ip 192.168.120.0 0.0.0.255 192.168.110.0 0.0.0.255
% c" I8 c; H% M' z: J3 ?: V x' N/ C deny ip 192.168.130.0 0.0.0.255 192.168.110.0 0.0.0.255
. T/ B, H4 M. r4 I9 ]- ` permit ip any any6 @5 l4 V3 _8 Y3 A
以上是路由器的配置,我发现日志一直会有错误信息
* |( \7 {: v& A. c: f& l. t3 g/ pDec 24 11:13:13 192.168.120.1 6319751: Dec 24 11:12:43.347: %ACLMGR-3-INVALIDPARAM: Invalid ACL type 5 encountered
6 _) g# L: W# U4 ?' Z5 TDec 24 11:13:13 192.168.120.1 6319752: -Traceback= 182FB44 17FE088 1EFBC68 1EF26E0
7 w. M; s- r, v* H2 `
- d6 ?8 d* i- }我想应该是自反列表的问题吧!能不能帮我分析下哪里出了问题。谢谢 |
|